QID 379585
QID 379585: Gitlab Malicious Runner Attachment via GraphQL Vulnerability (prior to gitlab- 15.11.2, 15.10.6, 15.9.7)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-2478: Malicious Runner Attachment via GraphQL
Affected Versions:
15.11.0, 15.11.1, 15.10.0, 15.10.1, 15.10.2, 15.10.3, 15.10.4, 15.10.5, 15.9.0, 15.9.1, 15.9.2, 15.9.3, 15.9.4, 15.9.5, 15.9.6, and below
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to Malicious Runner Attachment via GraphQL
Solution
GitLab has released patch addressing the vulnerability. For more information please refer to GitLab Critical Security Release: 15.11.2, 15.10.6, and 15.9.7
Vendor References
- GitLab Critical Security Release: 15.11.2, 15.10.6, and 15.9.7 -
about.gitlab.com/releases/2023/05/05/critical-security-release-gitlab-15-11-2-released/
CVEs related to QID 379585
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Critical Security Release: 15.11.2, 15.10.6, and 15.9.7 |
|